CVE-2025-64054
x210 firmware, x210
A reflected Cross Site Scripting (XSS) vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentially execute arbitrary commands via crafted POST request to the /cgi-bin/webconfig?page=upload&action=submit endpoint.
- CVSS
- 9.6
- EPSS
- 0.43% 35.3% percentile
- CISA KEV
- Not listed
- Published
- 2025.12.06